Kaseya Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Kaseya products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

4

In CISA KEV

2

Beyond CISA KEV

2

Sensor Observed

0

Virtual Patch Available

0

Kaseya KEVs Added by Year

Loading...

4 Kaseya KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2021-30118

Unauthenticated Remote Code Execution in Kaseya VSA < v9.5.5

High Not in CISA 18 Dec 2025
CVE-2021-30116

Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6

Confirmed In CISA 03 Nov 2021
CVE-2018-20753

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell...

Confirmed In CISA 13 Apr 2022
CVE-2015-2863

Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1...

High Not in CISA 20 Jul 2015

Common Vulnerability Classes (CWE)

  • CWE-434 — Unrestricted Upload of File with Dangerous Type 1
  • CWE-522 — Insufficiently Protected Credentials 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology